KryptosAI/mcp-observatory
View on GitHub ↗CI-native security testing for MCP servers. Attack simulation, schema drift detection, and health scoring before agents depend on them.
176 ★21 forksHTMLUpdated 18d ago
What you need to know
CI-native security and regression tool for MCP servers - catches broken tools, unsafe schemas, schema drift and security issues, and is itself an MCP server
Install
npx @kryptosai/mcp-observatory demo Add CI with npx @kryptosai/mcp-observatory setup-ci --all
Usage
- •Scan all configured MCP servers with npx @kryptosai/mcp-observatory
- •Add as an MCP server with claude mcp add mcp-observatory -- npx -y @kryptosai/mcp-observatory serve
Key features
- ✓Attack simulation, schema drift detection and record/replay/verify workflows
- ✓Security scanning for shell injection surfaces and credential leakage
- ✓Health scoring 0-100 with verdicts and badges
- ✓SARIF and GitHub Code Scanning output plus PR comments
- ✓MCP server mode with 10 tools for AI agents
- ✓Command allowlist and path validation against prompt injection
- ✓CI setup that generates GitHub Actions workflows
Best for
Teams shipping custom MCP servers who need CI security, drift and health checks
Caveats
- ⚠Servers requiring interactive OAuth need pre-authentication
- ⚠Custom WebSocket transports are not supported
- ⚠Production support through a paid pilot program
Platforms: Local · CIClients: Claude Code
Reviewed 2026-08-11
Topics
agent-securityai-agentai-securityai-supply-chainclicode-scanningdeveloper-toolsgithub-actiongithub-code-scanningmcpmcp-cimcp-securitymcp-servermcp-testingmodel-context-protocolregression-testingsarifschema-driftsecuritysupply-chain-security
- Stars
- 176★
- Forks
- 21
- Language
- HTML
- License
- MIT
- Created
- 2026-03-19
- Last push
- 2026-08-18